Opens an external site
- Employment type
- Contract
- Experience level
- Lead · 10+ years
- Minimum education
- Professional degree
- Apply by
- Oct 29, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 2 days per week
- Seniority
- Mid-Senior level
- Application method
- Direct apply is available
Job summary
Own and evolve enterprise security architecture and standards, leading security design across identity, cloud, network, endpoint, and AI environments in support of the organization’s Zero Trust vision. Provide hands-on design guidance and implementation partnership, advise on security risks and controls, support incident response, and communicate architecture decisions to technical teams and executives.
Job details
Position title: Security Architect Work Type: Hybrid working arrangements with a minimum of 2 days in the office per week Location: Mississauga Top 3 Skills / Priorities Security Architect with focus on IAM – this is the first Identity & Access Management (IAM) – Major priority. The organization is migrating from ADFS to a new platform, involving approximately 11,000 users. 5+ years in a security architecture or senior security engineering/Lead role. This is what they are specifically looking for: strong solution design and greenfield implementation experience. They need someone who can take a requirement, design the architecture, make the technical design decisions, and implement the platform from the ground up—rather than someone whose experience is primarily maintaining and administering an existing Microsoft environment. Team / Reporting Structure Reports to the Senior Director, Information Security. The successful candidate will have a high level of autonomy and ownership in this role. In addition to working closely with the Senior Director, the candidate will have direct interaction and visibility with senior leadership, including the CFI and CTO. Strong communication and stakeholder management skills are essential, as the individual must be comfortable communicating technical/security matters to senior executives. The Opportunity Seeking a Security Architect to join the Information Security team as a senior technical leader. In this role, you will define and drive enterprise security architecture strategy in support of a multi-year information security roadmap and Zero Trust Architecture vision. You will translate business and risk objectives into secure, scalable technical designs across our identity, cloud, network, and endpoint environments - and act as the trusted security design authority for technology and business initiatives across the organization. This is a hands-on architecture role: you will set standards and reference architectures, but you will also work directly in the platforms you design for, partnering with other members of the security, infrastructure, and application teams to see designs through to implementation. Key Accountabilities Own and evolve enterprise security architecture, reference architectures, and design standards in alignment with the information security strategy and Zero Trust Architecture principles. Lead security design for identity and access management, including authentication, authorization, federation, privileged access, and conditional access design across Active Directory, ADFS and Entra ID environments. Mature network security architecture, including secure access (SSE/SASE), network segmentation, and least-privilege access models. Define and continuously improve the security posture of Microsoft 365 and Azure, including Purview (DLP, sensitivity labels, retention), Exchange Online, SharePoint Online, and Entra ID configuration baselines. Provide security design review and consultation for new projects, applications, cloud services, and infrastructure changes, embedding security requirements early in the lifecycle. Lead design of Agentic AI security strategy Develop and maintain security standards, patterns, and hardening baselines Partner with security operations on detection and response architecture, ensuring telemetry, logging, and control coverage across endpoints, identity, email, and network layers. Assess and advise on the security of third-party and SaaS solutions, including AI-enabled platforms, as part of vendor risk and technology intake processes. Contribute to incident response as a senior technical escalation point, and translate lessons learned into architectural improvements. Communicate architecture decisions, risks, and trade-offs clearly to technical teams and executive stakeholders, including contributions to board- and committee-level reporting. Qualifications Education: University/College degree Certificate (CISSP, CISA, CSIM, CRISC)- Nice to have Skills & Abilities: 10+ years of progressive experience in information security, with 5+ years in a security architecture or senior security engineering role. Deep expertise in identity and authorization: Entra ID / Azure AD, Active Directory, ADFS or modern federation (SAML, OIDC, WS-Federation), conditional access, MFA, and privileged access management. Strong working knowledge of zero trust network architecture and its practical application to networks, identity, endpoints, and data. Proven experience securing Microsoft 365 and Azure at enterprise scale, including Purview, and cloud security posture management. Experience designing and operating email security, web security, and endpoint detection and response controls in a layered defence model. Ability to produce clear architecture artifacts: reference architectures, design documents, standards, and threat models. Good understanding of evolving AI tools, MCPs and associated risks Strong communication skills, with the ability to influence stakeholders from engineers to executives. Preferred Product Experience Cisco Umbrella / Cisco Secure Access (SWG, DNS security, secure client) Microsoft 365 security and compliance stack (Defender, Purview, Entra ID) Proofpoint (email protection, targeted attack protection) CrowdStrike Falcon (EDR, identity protection, exposure management, NG-SIEM) Preferred background Relevant certifications such as CISSP, CISSP-ISSAP, SABSA, CCSP, or equivalent. Experience with security frameworks and risk methodologies (CIS Controls, NIST CSF, CIS RAM). Exposure to AI governance and securing AI-enabled or agentic platforms. University Degree in Computer Science or related discipline Working Conditions Hybrid working arrangements with a minimum of 2 days in the office per week Occasional need to work outside of office hours
What you’ll do
Own and evolve enterprise security architecture and standards, leading security design across identity, cloud, network, endpoint, and AI environments in support of the organization’s Zero Trust vision. Provide hands-on design guidance and implementation partnership, advise on security risks and controls, support incident response, and communicate architecture decisions to technical teams and executives.
Requirements
Requires 10+ years of progressive information security experience, including at least 5 years in security architecture or a senior security engineering role, with deep expertise in identity, federation, access controls, and enterprise Microsoft environments. Candidates should have practical Zero Trust and cloud security experience, strong architecture documentation and communication skills, and a university or college degree; relevant certifications are desirable.
Listed skills
- Conditional Access · Preferred
- Active Directory · Preferred
- Stakeholder Management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Identity And Access Management
- Security Architecture
- Entra ID
- Active Directory
- ADFS
- Zero Trust Architecture
- Microsoft 365 Security
- Azure Security
- Conditional Access
- Privileged Access Management
- Network Security
- Cloud Security
- Security Design
- Threat Modeling
- Stakeholder Management
- AI Security
Job areas
- Security & Safety
- Technology
- Management & Leadership
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Bédard Ressources Humaines
ITAD Services Representative #1265
SponsoredDirect employerEasy Apply- On-site
- Mississauga, ON
- Posted Sep 16, 2026
EVAMAX Inc.
Tax Analyst - SR&ED
SponsoredDirect employerEasy Apply- Hybrid
- Oakville, ON
- Posted Sep 29, 2026
The Properties Group Management Ltd.
Real Estate Law Clerk
SponsoredDirect employerEasy Apply- On-site
- Ottawa, ON
- Posted Sep 24, 2026
